==========================================================Ubuntu Security Notice USN-1020-1         December 09, 2010
thunderbird, thunderbird-locales vulnerabilities
CVE-2010-3768, CVE-2010-3776, CVE-2010-3777, CVE-2010-3778
==========================================================
A security issue affects the following Ubuntu releases:

Ubuntu 10.04 LTS
Ubuntu 10.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 10.04 LTS:
  thunderbird                     3.1.7+build3+nobinonly-0ubuntu0.10.04.1

Ubuntu 10.10:
  thunderbird                     3.1.7+build3+nobinonly-0ubuntu0.10.10.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

Details follow:

Jesse Ruderman, Andreas Gal, Nils, Brian Hackett, and Igor Bukanov
discovered several memory issues in the browser engine. An attacker could
exploit these to crash THunderbird or possibly run arbitrary code as the
user invoking the program. (CVE-2010-3776, CVE-2010-3777, CVE-2010-3778)

Marc Schoenefeld and Christoph Diehl discovered several problems when
handling downloadable fonts. The new OTS font sanitizing library was added
to mitigate these issues. (CVE-2010-3768)


Updated packages for Ubuntu 10.04 LTS:

  Source archives:

          Size/MD5:     2512 8bba2a29930fd4f47bb2113433cd3780
          Size/MD5: 10177112 61d1828843d93c18d6ccadec7b62b5e0
          Size/MD5:    96568 178d17258c92d2827b2058132084e404
          Size/MD5:     2455 2bd12921e17b465b3ded0ed90b992e93
          Size/MD5: 66547472 b42dba1a96ac40207d521e40965642a2

  Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/
      Size/MD5:   216048 c0e8b31ce3970cb21f5327f9096e8d87
          Size/MD5:   223704 f95310a6344a3f351efb2c3636ea8bc0
          Size/MD5:   243786 6e51d35f574bb8509ba36ada0bf6e7dc
          Size/MD5:   208158 1b43018b36c30cb14391dd58e1b2d3aa
          Size/MD5:   248546 a9e6da035931c59a0706526cbc9a6617
          Size/MD5:   258092 9bf30ec268556aa84ed8aeab25a463f9
          Size/MD5:   232714 1b8c883abfb8d2bd3212dadff9a79ffa
          Size/MD5:   231952 0ae5849a9555fc1a21731074ca4a1261
          Size/MD5:   216500 8689c7073f96a7614154037a35042a1c
          Size/MD5:   236248 ec7ff62603cee0451217ac169e442567
          Size/MD5:   223694 e41018242c4a57e6b08329665ab61f8a
          Size/MD5:   217158 211482de902a07e4a60c91dcdb5bced9
          Size/MD5:   231928 083f32cd8b8c1b0ba7813672241ee861
          Size/MD5:   186366 6ea51e1c75b6a45e21cdff0fe3d7e405
          Size/MD5:   235200 17f39ff34817cfd4788c25d79e9391b5
          Size/MD5:   224534 a4594a7fbeb4e4c3aa3d7d33a937444b
          Size/MD5:   232940 f0ae0d20dbf6cb037bd5de853c7cb660
          Size/MD5:   235168 2492418cc7e106ed6cbd5aae7f28b50c
          Size/MD5:   234526 56831ea1196afd7e6fc8c7cd7bd21ba2
          Size/MD5:   232964 464df383bddbfd11018dd2bf1cc42f96
          Size/MD5:    13368 79ab394f402f45f02608034e56d0d67a
          Size/MD5:   218532 1846a1c34e83183c2a8c3061967f4c1c
          Size/MD5:   239488 3c67eeffcf2ce467f4394b8b80821b27
          Size/MD5:   199402 4bf2c9db385973abb215e015c117545a
          Size/MD5:   227302 f62764c5de81f9c439118ffab0853ff3
          Size/MD5:   184946 ac575826175e19df7d176f663b48b2ee
          Size/MD5:   250042 3cb41b704bce33a9434538ce6a7042f5
          Size/MD5:    13366 aa3e406f8dc40ad06ae081e30fc29653
          Size/MD5:   208420 e06634cff5a89e4b89d5797c02e10676
          Size/MD5:   248470 1d2e68b671a8c5a6ebd729adf752303d
          Size/MD5:    13368 f91b53e08c989380cd2586fb43b7d93b
          Size/MD5:   227242 ce90d5366a11228df5a3c354393235cf
          Size/MD5:   229924 b02cb5bf6c155b6ec1b3dd955365ac0a
          Size/MD5:   228510 6c725b79ebe44a19e2eb0f928756e87f
          Size/MD5:   254398 4c879777793012582bfb02f8be492424
          Size/MD5:   217350 cb692de845bd9567933802c3eba1aa98
          Size/MD5:   228428 f62e945d78c4b64c01154d553037ab5d
          Size/MD5:   227568 a91809d7469bcd5894784b856e92a547
          Size/MD5:   234586 7bbb9c84d2907d973ad55937d6e974b9
          Size/MD5:   211926 75a64a6ff54dd9e97f1838e81264a541
          Size/MD5:   259302 9e31b5ab52c92b9e9b46f616a7ca7ce0
          Size/MD5:   237654 b230c4b132fe4923486ff74502f5fd63
          Size/MD5:   231252 9eb127119110b038b0676c11eec7af52
          Size/MD5:   224558 1ec3354e9ff1dc6fee6ad5172bae8a6b
          Size/MD5:    13370 8780d011bccf01a14397d11327ca21bf
          Size/MD5:   234632 69b50dddc135ade075889bd93b844cc9
          Size/MD5:    13374 b74e92a89a3041f00f404d996eb28f09
          Size/MD5:   229128 2e68d3948bce80f71fb0188db30e7d27
          Size/MD5:   258190 285131071186e4ea0a7306baa898b657
          Size/MD5:   234504 4cd9c996ee23ee21d879584e30dca7c0
          Size/MD5:   232890 fba4f41bbfcf61f53eda7804cc6fe7b3
          Size/MD5:   233728 461eb4c334dfda7b0c3b42518a132afb

  amd64 architecture (Athlon64, Opteron, EM64T Xeon):

          Size/MD5: 63000172 8109b69daabaa3fefff3a37e29bd297f
          Size/MD5:  5010986 b1779755830dfa21b9492515aaecdad8
          Size/MD5:   180890 4a8246cec1b9e7e2afece90b3a3114d9
          Size/MD5:     9350 9ce162ff116f02bddc41c7f52617eca7
          Size/MD5: 12097428 d7ffde7091a6bb7da973f5515c09bd9b

  i386 architecture (x86 compatible Intel/AMD):

          Size/MD5: 63534166 4147ebf5b1bef56ea2c2c485369f9f11
          Size/MD5:  5590126 11bfced0ac5ab36eb56ccaa6375780cb
          Size/MD5:   180062 11d8661f181fb2c6e808ccc7d97f4c90
          Size/MD5:     9364 63762e1e2f95802c3a8e68a6692b9318
          Size/MD5: 11134562 80ee6584efd11a83ee7acc94cb9d9961

  armel architecture (ARM Architecture):

          Size/MD5: 64382450 3ff39898841ca2aec4a357dfd32341cd
          Size/MD5:  5476316 a2dc3fe2cda0f8728bd93a5f0b9cd89a
          Size/MD5:   182418 fe2fbf5e1d31b97f594994d38bec1ec1
          Size/MD5:     9360 944bf59bbd62fc016604737a4919cd20
          Size/MD5: 10762750 e38b37099107fde5ddf5bc223f77038a

  powerpc architecture (Apple Macintosh G3/G4/G5):

          Size/MD5: 66020146 2a71167abe453f888eb771db486e2281
          Size/MD5:  4984466 37cdf8d4f9092be84a7ab86a1fd8a8b9
          Size/MD5:   186756 22b22e86e980e8064be8a498dfcfe4f8
          Size/MD5:     9356 3e624a65ca4ea923adc11039d1420860
          Size/MD5: 11926748 23dd7b1311f1d2d426c75f26f3804c55

  sparc architecture (Sun SPARC/UltraSPARC):

          Size/MD5: 62414254 6598c709e870247936840a8e3ccb441b
          Size/MD5:  4951766 180eb8482b83850152a92d479601070c
          Size/MD5:   176192 413f06140c197feaea20e46c69983077
          Size/MD5:     9358 e58dfccbbffd68e4fa026e967e2b96df
          Size/MD5: 11138460 1540d3a6e743908cb05cd92f193ffdb6

Updated packages for Ubuntu 10.10:

  Source archives:

          Size/MD5:    97591 24a6fb7619ee344addaca503d59e4a78
          Size/MD5:     2468 be9e34c54a43908ffdfbff3d2981bcce
          Size/MD5: 66547472 b42dba1a96ac40207d521e40965642a2

  amd64 architecture (Athlon64, Opteron, EM64T Xeon):

          Size/MD5: 63010010 603e6566786bf0d152b70c83147457cf
          Size/MD5:  5434698 733cdd62685cd337d83de40cde2a83c1
          Size/MD5:   181598 13bed53e0b5f114e944e6c497992d7b4
          Size/MD5:     9376 b87520aca04aacfc08ffbdc81ec7e47c
          Size/MD5: 12092612 940994b81ebcee158b538fb9046d73d3

  i386 architecture (x86 compatible Intel/AMD):

          Size/MD5: 63528528 fd1c66222f7d3632b2b9ac1045bd8709
          Size/MD5:  5148622 076ac89a8c00f5f3ea9813017ac8005d
          Size/MD5:   180712 2c18e038b5a39a4e85a66bd16cea5aee
          Size/MD5:     9374 17ae41ed1fa9e500efc2e355fde4efad
          Size/MD5: 11099108 ea230acbd3a4e520a739f1119f2714b6

  armel architecture (ARM Architecture):

          Size/MD5: 66027622 494f04e9036ff5d84908384f8ccd6436
          Size/MD5:  5659900 9d2ab98ad4fbf2c3a2c12a66af917867
          Size/MD5:   188826 ea80a0a7d968e4d0c7694c1cfc21f053
          Size/MD5:     9380 475f01ba44be402daaf0017e8b16dac1
          Size/MD5: 10980942 ccb42f729c4d8c93112d4068c8390b2f

  powerpc architecture (Apple Macintosh G3/G4/G5):

          Size/MD5: 65819262 8c330beaf6972f7602ccf12302e3693d
          Size/MD5:  4982016 f219a630db4f124c1cdfeac357cc224c
          Size/MD5:   187328 7f17dbc49d1747f1b021702b5a12694f
          Size/MD5:     9378 9bca50f688d98967095009706664fe55
          Size/MD5: 11788756 a547aa7b18a21212330f5b59eb9d27a2



Ubuntu 1020-1: Thunderbird vulnerabilities

December 9, 2010
Jesse Ruderman, Andreas Gal, Nils, Brian Hackett, and Igor Bukanov discovered several memory issues in the browser engine

Summary

Update Instructions

References

Severity
thunderbird, thunderbird-locales vulnerabilities

Package Information

Related News